Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A software company is pursuing ISO/IEC 27001 certification. The ISMS scope covers its cloud-hosted product and corporate IT. An auditor requests evidence that management reviews the ISMS at planned intervals. Which artifact should the security manager provide?

⚠ Common exam trap

The trap here is treating any governance-related document, such as the Statement of Applicability, as proof of management review without matching it to clause 9.3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Management review meeting minutes with inputs, decisions, and actions

Clause 9.3 of ISO/IEC 27001 mandates that top management review the ISMS at planned intervals, considering status of actions, changes, performance feedback, and risk assessment results. Documented minutes capturing inputs, decisions, and resulting actions are the direct evidence auditors seek. Other artifacts such as internal audit reports or the Statement of Applicability may feed the review but do not demonstrate that it took place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The latest internal audit report and nonconformity log

    Why it's wrong here

    Internal audit reports and nonconformity logs are evidence for clause 9.2 and corrective action processes, not for management review under clause 9.3. They may be inputs to a management review, but on their own they do not prove that top management conducted a review. The auditor specifically asked for management review evidence.

  • ✗

    Business continuity and disaster recovery test results

    Why it's wrong here

    Business continuity and disaster recovery test results relate to availability and resilience controls, often under Annex A 5.29 and 5.30. They are not evidence of management review under clause 9.3. Submitting them would not answer the auditor's request regarding planned management reviews of the ISMS.

  • ✗

    The Statement of Applicability listing implemented controls

    Why it's wrong here

    The Statement of Applicability documents which Annex A controls are applicable and why, supporting clause 6.1.3. It does not record management's periodic evaluation of the ISMS. While it may be reviewed during a management review, it is not the artifact that demonstrates the review occurred.

  • ✓

    Management review meeting minutes with inputs, decisions, and actions

    Why this is correct

    ISO/IEC 27001 clause 9.3 requires top management to review the ISMS at planned intervals, and documented minutes showing inputs, decisions, and actions are the expected evidence. These records demonstrate that leadership evaluated performance, risks, and opportunities and directed changes. Providing them directly satisfies the auditor's request for management review evidence.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.